[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-03-10。"],[[["Container Registry uses Cloud Storage to store container images, and Cloud Storage encrypts data server-side by default."],["For compliance, customer-managed encryption keys (CMEK) can be used to encrypt container images stored in Container Registry, allowing control over access by disabling or destroying the key."],["Organization policy constraints, particularly those related to Cloud Storage and Pub/Sub APIs, can affect Container Registry usage, such as preventing image pushes or requiring CMEK for new storage buckets and Pub/Sub topics."],["If `constraints/gcp.restrictNonCmekServices` is enforced, you cannot push images to Container Registry, and Artifact Registry is recommended as an alternative."],["Container Registry can use CMEK by leveraging storage buckets configured with CMEK in Cloud Storage; however, this is impossible if `constraints/gcp.restrictNonCmekServices` is being used."]]],[]]